{"id":"GHSA-9vhv-p9r7-rm53","summary":"HTML tag injection","details":"Serve Handler, before 5.0.3, has a XSS via HTML tag injection in directory lisiting page.","modified":"2021-02-23T21:37:48Z","published":"2021-02-23T21:37:48Z","withdrawn":"2021-02-23T21:37:48Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2019-06-06T08:49:37Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/zeit/serve-handler/commit/65b4d4183a31a8076c78c40118acb0ca1b64f620"},{"type":"WEB","url":"https://hackerone.com/reports/398285"}],"affected":[{"package":{"name":"serve-handler","ecosystem":"npm","purl":"pkg:npm/serve-handler"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-9vhv-p9r7-rm53/GHSA-9vhv-p9r7-rm53.json"}}],"schema_version":"1.9.0"}